Privacy notice
Last updated 16 September 2026 · Liverpool pilot
Who we are
CornerMile is run-club software for hospitality venues, currently in a Liverpool pilot. For anything in this notice — questions, access requests, corrections or deletion — email security@cornermile.co.uk, the monitored contact address during the pilot.
What we collect, and why
Venue teams: your email, venue name and address, and team roles — to run your account. Runners: your email, optional display name, club memberships, RSVPs, verified check-ins and any rewards earned — to run the club you joined. Emergency contact details are optional, controlled by you, visible to run leaders only around a run, and never exported. Consents: when you opt into run updates or venue news we store the exact wording you agreed to and when — and the same when you withdraw. Launch list: if you register interest from outside the pilot area we store your name, venue, contact details, location and role so we can email you launch and product updates you asked for, and to understand where demand is. Leader interest: if you register to lead a run club we store your name, contact details, location, social handle and the optional notes you give us about your audience and availability — so we can email you about venues looking for a run leader and match you with clubs, by hand, at pilot scale. Runner interest: if you ask to hear when a club opens near you we store your email, the town or city you gave, an optional first name and postcode area, and the exact wording you agreed to — so we can email you when a club opens there and see where runners are waiting. Searching the club directory stores nothing; only that form does.
What we don't do
No advertising, no selling or renting data, no tracking pixels in email (deliberately, we don't use open tracking), no advertising or cross-site tracking cookies anywhere, no profiles built about individual people, and no sending marketing without an explicit opt-in. Emails you receive because you RSVP'd to a run, such as cancellations and time changes, are service messages, not marketing. Nothing in the measurement described below is ever used to decide what to send you, and none of it is linked to your email address.
How we measure the pilot
We need to know where people get stuck signing a venue up, joining a club or checking in, so we can fix it. Two things do that, and neither builds a picture of you. A short-lived journey marker: when you start signing up, joining or checking in, we set a first-party cookie holding a random reference that means nothing anywhere else. It lasts 30 minutes, your browser cannot read it, and it lets us count steps like "asked for a code" and "came back with the code". What we store against it is a fixed list of step names plus whether you arrived from a search, a QR code, social or a link. We never store your name, email, postcode, IP address, browser, what you typed, or the address of the page you came from. Help given by hand: if we help someone through a step, we record what kind of help it was, at which step, and how it ended — with no notes, nothing about the person, and no record of which of us helped. What is deleted, and when: after 90 days the step records and the assistance records are deleted, and the random journey reference that links them goes with them. What survives is counts and timings that name nobody and cannot be traced back: how many journeys reached a step on a given day and how long that typically took, and how many times each kind of help was needed at each step. There is no way to get from those counts to a person, a session or a device. Page and speed statistics: the code for Cloudflare Web Analytics is built in but not switched on. It is privacy-first, sets no cookie, and reports page views and loading speed without identifying visitors — but it stays inactive until a Cloudflare site and token are set up, so nothing is being sent to it today, and when it is switched on it will run on the live site only. Our lawful basis for both is legitimate interests: running and improving a service you are using. It is not marketing, it is kept separate from every consent you give us, and opting out of run updates or venue news has no effect on it either way.
Where your data lives
Data is stored with Supabase in London (UK/EU region) and served through Cloudflare. Emails are sent through Brevo, an EU-based email provider. We never store your email address inside the email queue itself — messages resolve the address only at send time.
How long we keep things
Venue data: while the account is active; when a venue is deleted, a support-recoverable snapshot is kept for 30 days and then permanently purged. Runner data lives with the club it belongs to and is purged with it. Launch-list, leader-interest and runner-interest entries: until you unsubscribe (one click in any email) or ask us to delete your entry. Concern reports and audit records are kept as long as safeguarding and accountability require. The onboarding step records and the assistance records described above are deleted 90 days after they are made — including the random journey reference — leaving only the counts and timings above, which identify nobody.
Your rights
Under UK GDPR you can ask for a copy of your data, correction, deletion, or restriction of processing, and you can withdraw any consent at any time — consents have controls in the product, and every marketing email has a one-click unsubscribe. Email security@cornermile.co.uk to exercise any of these. If you're unhappy with how we handle your data you can complain to the ICO at ico.org.uk.
Changes to this notice
We'll update this page as the product grows — the date below always reflects the current version. Consent wording shown at the moment you opted in is stored verbatim with your record, so later copy changes never rewrite what you actually agreed to.
Looking for the launch list? It's here. Want to lead a club? Register as a run leader.